GitHub Actions执行git push遇认证错误,求非交互式token传参方案
如何在GitHub Action中无交互完成Git推送认证(不暴露Token也不修改origin URL)
问题描述
我正在编写一个GitHub Action,流程为:1. Fork仓库;2. 创建分支;3. 修改内容;4. 推送修改到远程仓库。但执行推送步骤时遇到错误:
fatal: could not read Username for 'https://github.com': No such device or address
推测是Git触发了交互式认证导致的。已知可以通过在远程URL中嵌入GitHub Token来解决,但这种方法有两个问题:一是需要修改或硬编码origin URL,而我想保留gh repo fork生成的原始URL;二是Token会明文暴露。请问有没有非交互式的方式传递Token完成认证?
我的Workflow配置如下:
name: Release on: push: branches: - main workflow_dispatch: inputs: manual_release: description: "Manually trigger doc build and release." required: false default: false jobs: release: name: Release runs-on: ubuntu-latest permissions: write-all - name: Setup git id: setup-git if: ${{ steps.setup-pandoc.conclusion == 'success' }} run: | git config --global user.name "cookiecutter-dash-docset" git config --global user.email "cookiecutter.dash.docset@users.noreply.github.com" - name: Fork env: GITHUB_TOKEN: ${{ secrets.GH_TOKEN }} run: | gh repo fork --clone Kapeli/Dash-User-Contributions - name: Branch working-directory: ./Dash-User-Contributions run: | git switch --create=${{ github.run_id }}-${{ github.run_attempt }} - name: Make a change working-directory: ./Dash-User-Contributions run: | echo 'change ' > file.txt - name: Commit working-directory: ./Dash-User-Contributions run: | git add --all git commit --message="Change!" - name: Push working-directory: ./Dash-User-Contributions run: | git push --set-upstream origin ${{ github.run_id }}-${{ github.run_attempt }}
解决方案
方法1:用gh auth setup-git自动配置认证(推荐)
既然你已经在使用gh CLI执行Fork操作,且已经传入了GITHUB_TOKEN,可以直接让gh帮Git配置好认证规则,后续所有Git操作都会自动用Token完成非交互认证:
在Setup git步骤后添加一个配置步骤:
- name: Configure Git auth via gh CLI env: GITHUB_TOKEN: ${{ secrets.GH_TOKEN }} run: | gh auth setup-git
之后你的Push步骤可以完全保留原来的命令,不需要任何修改。gh auth setup-git会自动配置Git的凭证助手,让Git通过gh获取认证信息,全程不会暴露Token,也不需要修改origin URL。
方法2:临时配置Git凭证助手
通过临时生成凭证文件的方式让Git自动读取认证信息,推送后立即清理文件避免Token残留:
- name: Push working-directory: ./Dash-User-Contributions env: GITHUB_TOKEN: ${{ secrets.GH_TOKEN }} run: | # 配置临时凭证文件 git config credential.helper 'store --file=/tmp/git-credentials' echo "https://${GITHUB_TOKEN}:x-oauth-basic@github.com" > /tmp/git-credentials # 执行推送 git push --set-upstream origin ${{ github.run_id }}-${{ github.run_attempt }} # 清理凭证文件 rm /tmp/git-credentials
方法3:通过HTTP请求头传递Token
给Git设置临时的HTTP请求头,携带Authorization信息,完成推送后取消配置:
- name: Push working-directory: ./Dash-User-Contributions env: GITHUB_TOKEN: ${{ secrets.GH_TOKEN }} run: | git config http.extraHeader "Authorization: token ${GITHUB_TOKEN}" git push --set-upstream origin ${{ github.run_id }}-${{ github.run_attempt }} git config --unset http.extraHeader
优化后的完整Workflow示例(用方法1)
name: Release on: push: branches: - main workflow_dispatch: inputs: manual_release: description: "Manually trigger doc build and release." required: false default: false jobs: release: name: Release runs-on: ubuntu-latest permissions: write-all steps: - name: Setup git id: setup-git # 注意:原配置中引用的steps.setup-pandoc不存在,建议移除该条件或补充对应步骤 # if: ${{ steps.setup-pandoc.conclusion == 'success' }} run: | git config --global user.name "cookiecutter-dash-docset" git config --global user.email "cookiecutter.dash.docset@users.noreply.github.com" - name: Configure Git auth via gh CLI env: GITHUB_TOKEN: ${{ secrets.GH_TOKEN }} run: | gh auth setup-git - name: Fork env: GITHUB_TOKEN: ${{ secrets.GH_TOKEN }} run: | gh repo fork --clone Kapeli/Dash-User-Contributions - name: Branch working-directory: ./Dash-User-Contributions run: | git switch --create=${{ github.run_id }}-${{ github.run_attempt }} - name: Make a change working-directory: ./Dash-User-Contributions run: | echo 'change ' > file.txt - name: Commit working-directory: ./Dash-User-Contributions run: | git add --all git commit --message="Change!" - name: Push working-directory: ./Dash-User-Contributions run: | git push --set-upstream origin ${{ github.run_id }}-${{ github.run_attempt }}
内容的提问来源于stack exchange,提问作者Paulo Costa
相关产品推荐
相关产品推荐

